CVE-2025-66648

EUVD-2025-206236
vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites that allow users to supply untrusted user input, malicious use of an internal function (not part of the public API) could be used to run unintentional javascript (XSS). This issue is fixed in vega-functions `6.1.1`. There is no workaround besides upgrading. Using `vega.expressionInterpreter` as described in CSP safe mode does not prevent this issue.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
7.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9.07%
Affected Products (NVD)
VendorProductVersion
vega-functions_projectvega-functions
𝑥
< 6.1.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
vega_projectvega
𝑥
< 6.1.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
vega.js
bookworm
no-dsa
forky
5.33.1+ds+~cs5.3.0-4
fixed
sid
5.33.1+ds+~cs5.3.0-4
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vega.js
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage